Host risk evaluation framework based on multi-source information

Gao Cuixia,Li Zhitang,Chen Lin
DOI: https://doi.org/10.1109/CCCM.2009.5270459
2009-01-01
Abstract:A framework was designed for fusing security information from multiple sources to evaluate host security risk. We selected four types of information that may good indicators of host security status, they are host resource usage, host real-time traffic, OS kernel files status and other security device information. In the information fusion module, the D-S evidence theory was used to fuse all the dynamic evidences. The weighted evidence was more effective on increasing the accuracy of the evaluation. In the calculation of weights of different variable the information entropy method was introduced to avoid subjectivity. An adaptive mechanism was also presented to adapt to dynamic host activities. Our framework is currently being developed for cyber security assessment. The initial experiments show that this framework is well suited to hardening critical infrastructure systems against cyber attack. ©2009 IEEE.
What problem does this paper attempt to address?